On Mon, 5 Oct 2026, Wei Chuang wrote:
Just following up here.  At the DKIM interim -05, PQC was discussed; the
direction is to use a composite aka hybrid: ML-DSA-44 / Ed25519 to support
PQC.  This would apply only to DKIM2, skipping DKIM1.  The belief is that
the update could be done as small text additions to existing drafts rather
than requiring a new internet-draft.  Assuming that, we'll need new text
for the draft-ietf-dkim-dkim2-spec and draft-ietf-dkim-dkim2-dns.

We heard that while that combo is the best guess at the moment for a PQ algorithm, it may not be in the future. So what's important is that we have at least two algorithms specified so we can test out key and algorithm rotation.

That reminds me, are we including RSA keys? The argument against was that ed25519 keys are better in every way, argument for was that there are a lot of published RSA keys people might want to keep using.

Regards,
John Levine, [email protected], Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail. https://jl.ly
_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to